St. Elizabeth’s Medical Center in Brighton, Mass., will pay a $218,400 fine and implement a HIPAA privacy/security corrective action plan under a settlement with the HHS Office for Civil Rights.

HHS/OCR in late 2012 received a complaint that employees at the hospital were using an unsecured Internet-based document sharing application that held protected health information for at least 498 individuals. OCR determined that the hospital “failed to timely identify and respond to the known security incident, mitigate the harmful effects of the security incident, and document the security incident and its outcome,” according to an agency announcement.

Register or login for access to this item and much more

All Health Data Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access